First published: Sun Jul 10 2005(Updated: )
Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Cisco IP phone 7940 firmware | ||
Cisco VoIP Phone CP-7940 | ||
All of | ||
Cisco IP Phone 7960 Firmware | ||
Cisco VoIP Phone CP-7960 | ||
Cisco 7960 Router | ||
Cisco 7940 Router |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-2181 is considered moderate, as it allows for spoofing of messages on affected Cisco VoIP phones.
To fix CVE-2005-2181, update the firmware of affected Cisco 7940 and 7960 VoIP phones to the latest version provided by Cisco.
CVE-2005-2181 affects Cisco 7940 and 7960 VoIP phones that do not properly check certain values in NOTIFY messages.
Yes, CVE-2005-2181 can be exploited remotely by attackers sending specially crafted NOTIFY messages.
CVE-2005-2181 can enable attackers to spoof messages like 'Messages waiting', potentially misleading users and affecting communications.